Sears Holdings Management Corporation

Sears Holdings Management Corporation

The Washington State Office of the Attorney General reported a data breach by Sears Holdings on April 24, 2018. The breach occurred from September 27, 2017, to October 12, 2017, affecting 2,373 individuals in Washington. The compromised information included names and payment card information due to a cyberattack involving malicious script inserted by an unauthorized individual.

Source: https://www.atg.wa.gov/data-breach-notifications | https://data.wa.gov/resource/sb4j-ca4h.json?id=9565

TPRM report: https://www.rankiteo.com/company/sears

"id": "sea949072525",
"linkid": "sears",
"type": "Cyber Attack",
"date": "9/2017",
"severity": "60",
"impact": "2",
"explanation": "Attack limited on finance or reputation"
{'affected_entities': [{'customers_affected': 2373,
                        'industry': 'Retail',
                        'location': 'Washington',
                        'name': 'Sears Holdings',
                        'type': 'Retail'}],
 'attack_vector': 'Malicious Script',
 'data_breach': {'data_exfiltration': True,
                 'number_of_records_exposed': 2373,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Names',
                                              'Payment Card Information']},
 'date_detected': '2018-04-24',
 'date_publicly_disclosed': '2018-04-24',
 'description': 'The Washington State Office of the Attorney General reported '
                'a data breach by Sears Holdings on April 24, 2018. The breach '
                'occurred from September 27, 2017, to October 12, 2017, '
                'affecting 2,373 individuals in Washington, with compromised '
                'information including names and payment card information due '
                'to a cyberattack involving malicious script inserted by an '
                'unauthorized individual.',
 'impact': {'data_compromised': ['Names', 'Payment Card Information'],
            'payment_information_risk': True},
 'initial_access_broker': {'entry_point': 'Malicious Script'},
 'post_incident_analysis': {'root_causes': 'Insertion of malicious script by '
                                           'an unauthorized individual'},
 'references': [{'date_accessed': '2018-04-24',
                 'source': 'Washington State Office of the Attorney General'}],
 'threat_actor': 'Unauthorized Individual',
 'title': 'Sears Holdings Data Breach',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Insertion of malicious script'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.